A software-defined radio can derail a US train by slamming the brakes on remotely
ID: ea3cc1f4-611c-5b3d-89f0-a66515541294
STIX ID: report--ea3cc1f4-611c-5b3d-89f0-a66515541294
Feed Name: The Register (Security)
CISA published CVE-2025-1727 (CVSS 8.1) describing weak authentication in the FRED end-of-train to head-of-train protocol used on freight trains, which allows attackers who can spoof radio traffic (e.g., via low-cost software-defined radios) to send braking commands and potentially cause stoppages or derailments; the protocol is end-of-life and a secure replacement (802.16t) is not expected until ~2027, leaving operators reliant on segmentation and basic mitigations while stakeholders monitor the issue.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
